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Executive  Summary 


Introduction.  This  report  is  one  in  a  series  of  reports  being  issued  by  the  Inspector 
General,  DoD,  in  accordance  with  an  informal  partnership  with  the  Chief  Information 
Officer,  DoD,  to  monitor  DoD  efforts  to  address  the  year  2000  computing  challenge. 
For  a  listing  of  audit  projects  addressing  this  issue,  see  the  year  2000  webpage  on  IGnet 
at  <http://www,ignet.gov>. 

Information  technology  systems  have  typically  used  two  digits  to  represent  the  ye^, 
such  as  “98”  representing  1998,  to  conserve  electronic  storage  and  reduce  operating 
costs.  With  the  two-digit  format,  however,  the  year  2000  is  indistinguishable  from 
1900.  As  a  result  of  the  ambiguity,  computers  and  associated  systems  and  application 
programs  that  use  dates  to  calculate,  compare,  and  sort  could  generate  incorrect  results 
when  working  with  years  after  1999. 

Audit  Objectives.  The  overall  audit  objective  was  to  evaluate  the  status  of  the  U.S. 
Central  Command’s  progress  in  resolving  the  year  2000  computing  issue.  CXir  audit 
focused  on  the  following  year  2000  issues:  leadership  support  Md  awareness, 
management  and  resolution  strategy,  system  assessments,  prioritization,  system 
interfaces,  testing,  risk  analysis  and  contingency  planning,  and  support  received  from 
responsible  Service  executive  agents. 

Audit  Results.  The  U.S.  Central  Command  has  recognized  the  importance  of  the  year 
2000  issue  and  has  taken  numerous  positive  actions  in  addressing  the  year  2(XX) 
problem.  The  progress  that  the  U.S.  Central  Command  made  in  resolving  the  ye^ 
2000  computing  issue  is  not  complete.  Unless  the  U.S.  Central  Command,  the  Joint 
Staff,  the  Services,  and  Defense  agencies  make  further  progress,  U.S.  Central 
Command  faces  a  high  risk  that  year-2000-related  disruptions  will  impair  its  mission 
capabilities.  See  Part  I  for  details  of  the  audit  results. 

Summary  of  Recommendations.  We  recommend  that  the  Commander  in  Chief,  U.S. 
Central  Command,  monitor  and  implement  revisions  to  the  DoD  Year  2000 
Management  Plan;  complete  the  identification  of  mission-critical  supporting  systems 
and  system  interfaces;  research  year  2000  compliance  of  vendor  so^are  and  test 
mission-critical  vendor  software;  prepare  written  interface  agreements  and  develop 
contingency  plans  for  mission-critical  systems  diat  the  U.S.  Central  Command 
manages;  document  test  plans  to  show  how  managed  systems  were  deemed  compliant 
and  determine  the  level  of  year  2000  compliance;  coordinate  year  2000  solutions  with 
the  Component  Commands;  and  use  selected  command  and  joint  exercises  to  test 


year  2000  scenarios  in  an  operational  environment.  We  recommend  that  the  Director, 
Joint  Staff,  develop  an  inventory  of  and  assist  the  unified  commands  in  obtaining  year 
2000  information  on  mission-critical  supporting  systems  diat  Services  or  other 
organizations  manage;  implement  procedures  to  monitor  and  track  the  status  of 
mission-critical  systems;  assist  the  united  conunands  in  testing  systems  and 
applications  conunon  to  the  unified  commands;  disseminate  year  2000  information  on 
commercial  off-lhe-shelf  products  and  Government  off-the-shelf  products;  and  use 
selected  joint  exercises  to  test  year  2000  scenarios  in  an  operational  environment. 

Management  Comments.  The  U.S.  Central  Command  and  the  Joint  Staff  concurred 
with  the  recommendations.  See  Part  I  for  a  summary  of  management  comments  and 
Part  m  for  the  complete  text  of  the  comments. 
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Audit  Background 

The  year  2000  (Y2K)  problem  is  the  term  most  often  used  to  describe  the 
potential  failure  of  information  technology  systems  to  process  or  perform 
date-related  ftmctions  before,  on,  or  after  the  turn  of  the  century.  The  Y2K 
problem  is  rooted  in  the  way  that  automated  information  systems  record  and 
compute  dates.  For  the  past  several  decades,  systems  have  typically  used  two 
digits  to  represent  the  year,  such  as  “98”  representing  1998,  to  conserve  on 
electronic  ^ta  storage  and  reduce  operating  costs.  With  the  two-digit  format, 
however,  2000  is  indistinguishable  from  1^.  As  a  result  of  the  ambiguity, 
computers  and  associated  systems  and  application  programs  that  use  dates  to 
calculate,  compare,  or  sort  could  generate  incorrect  results  when  working  with 
years  following  1999.  Calculation  of  Y2K  dates  is  further  complicated  because 
the  Y2K  is  a  leap  year,  the  first  century  leap  year  since  1600.  The  computer 
systems  and  applications  must  recognize  February  29,  2000,  as  a  valid  date. 

Because  of  the  potential  failure  of  computers  to  run  or  function  throughout  the 
Government,  the  President  issued  an  Executive  Order,  “Year  2000 
Conversion,”  February  4,  1998,  making  it  policy  that  Federal  agencies  ensure 
that  no  critical  Federal  program  experiences  disruption  because  of  the  Y2K 
problem.  The  Executive  Order  also  requires  that  the  head  of  each  agency 
ensure  that  efforts  to  address  the  Y2K  problem  receive  the  highest  priority 
attention  in  the  agency.  In  addition,  the  General  Accoimting  Office  has 
designated  resolution  of  the  Y2K  problem  as  a  high-risk  area,  and  DoD  has 
recognized  the  Y2K  issue  as  a  material  management  control  weakness  area  in 
the  FY  1997  Annual  Statement  of  Assurance. 

DoD  Y2K  Man^ement  Strategy.  In  his  role  as  the  DoD  Chief  Information 
Officer,  die  Assistant  Secretary  of  Defense  (Command,  Control, 
Communications,  and  Intelligence)  issued  the  “DoD  Year  2000  Management 
Plan”  (DoD  Management  Plan)  in  April  1997.  The  DoD  Management  Plan 
provides  the  overall  DoD  strategy  and  ^idance  for  inventorying,  prioritizing, 
fixing,  or  retiring  systems,  and  monitoring  progress.  The  DoD  Management 
Plan  states  that  the  DoD  Chief  Information  Officer  has  overall  responsibility  for 
overseeing  the  DoD  solution  to  the  Y2K  problem.  Also,  the  DoD  Management 
Plan  makes  the  DoD  Components  responsible  for  the  five-phase  Y2K 
management  process,  consisting  of  awareness,  assessments,  renovations, 
validations,  and  implementation  actions.  The  DoD  Management  Plan  includes  a 
description  of  the  five-phase  Y2K  management  process. 

The  Assistant  Secretary  of  Defense  (Command,  Control,  Communications,  and 
Intelligence)  is  in  the  process  of  issuing  an  updated  DoD  Management  Plan, 
which  accelerates  the  target  completion  dates  for  the  renovation,  validation,  and 
implementation  phases. 
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In  a  memorandum  dated  January  20,  1998,  for  the  heads  of  executive 
departments  and  agencies,  the  Office  of  Management  and  Budget  established  a 
new  target  date  of  March  1999  for  implementing  corrective  actions  to  all 
systems.  The  new  target  completion  dates  are  September  1998  for  the 
renovation  phase  and  January  1999  for  the  validation  phase. 

The  Joint  Chiefs  of  Staff.  The  Chairman  of  the  Joint  Chiefs  of  Staff  is  the 
principal  milit^  advisor  to  the  President,  the  Secretary  of  Defense,  and  the 
National  Security  Council.  The  Joint  Chiefs  of  Staff  have  no  executive 
authority  to  command  the  combatant  forces.  The  Secretaries  of  the  Military 
Departments  assign  all  forces  under  dieir  jurisdiction  to  the  unified  commands 
to  perform  missions  assigned  to  those  commands. 

The  Joint  Staff  Director,  Command,  Control,  Communications,  and  Computer 
Systems  (J6),  has  been  designated  by  the  Chairman  of  the  Joint  Chiefs  of  Staff 
to  oversee  the  unified  commands’  and  Joint  Staffs  implementation  of  the  DoD 
Management  Plan. 

The  Joint  Staff.  The  Joint  Staff  assists  the  Chairman  of  the  Joint  Chiefs 
of  Staff  with  unified  strategic  direction  of  the  combatant  forces;  unified 
operation  of  the  combatant  commands;  and  integration  into  an  efficient  team  of 
land,  naval,  and  air  forces. 

Year  2000  Action  Plan.  The  Joint  Staff  Year  2000  Action  Plan 
provides  the  unified  commands  and  Joint  Staff  directorates  the  corporate 
strategy  and  management  approach  for  addressing  the  Y2K  problem.  The 
action  plan  uses  the  accelerated  target  completion  dates  for  the  renovation, 
validation,  and  implementation  phases  in  the  draft  DoD  Management  Plan.  The 
action  plan  provides  that  the  unified  commands  should  target 
December  31,  1998,  for  completion  of  all  Y2K  efforts. 

U.S.  Central  Command.  The  U.S.  Central  Command  (CENTCOM)  is  one  of 
nine  unified  corrunands  in  the  Department  of  Defense.  I^e  CENTCOM  was 
activated  on  January  1,  1983.  The  CENTCOM  is  the  administrative 
headquarters  for  U.S.  military  affairs  in  20  countries  of  the  Middle  East, 
Southwest  Asia,  Northeast  AMca,  and  the  Arabian  Gulf.  That  region  contains 
more  than  70  percent  of  the  world’s  oil  reserves,  making  it  vital  to  the 
economies  of  the  United  States  and  its  allies.  The  CENTCOM  reports  through 
the  Chairman  of  die  Joint  Chiefs  of  Staff  to  the  Secretary  of  Defense.  The 
overall  mission  of  CENTCOM  is  to  support  U.S.  and  free-world  interests  by: 

•  oisuring  access  to  theater  oil  resources; 

•  helping  friendly  regional  states  to  maintain  their  own  security  and  a 
collective  defense; 
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•  maintaining  an  effective  and  visible  U.S.  military  presence  in  the 
region;  and 

•  deterring  threats  from  hostile  regional  states  and  providing  U.S. 
military  force  into  the  region,  if  necessary. 

The  CENTCOM  is  supported  by  component  commands  from  each  Service  that 
provide  forces  as  required  to  conduct  operations.  The  component  commands 
are  the  U.S.  Army  Forces  Central  Command,  the  U.S.  Naval  Forces  Central 
Command,  the  U.S.  Central  Command  Air  Forces,  and  the  Special  Operations 
Command  Central  Command.  Additionally,  the  Joint  Task  Force  South  West 
Asia  and  Security  Assistance  Offices  in  several  nations  complement  the  U.S. 
military  forces  in  the  region  by  coordinating  the  efforts  of  CENTCOM  with 
their  respective  host  nations. 


Audit  Objectives 

The  overall  audit  objective  was  to  evaluate  the  status  of  the  jprogress  of 
CENTCOM  in  resolving  its  Y2K  computing  issue.  Our  audit  focused  on  the 
following  Y2K  issues:  leadership  support  and  awareness,  management  and 
resolution  strategy,  system  assessments,  prioritization,  system  interfaces, 
testing,  risk  analysis  and  contingency  planning,  and  support  received  from 
responsible  Service  executive  agents.  See  Appendix  A  for  a  discussion  of  the 
audit  scope  and  methodology  and  summary  of  prior  audit  coverage,  and 
Appendix  B  for  other  matters  of  interest. 
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Status  of  the  U.S.  Central  Command 
Year  2000  Program 

The  CENTCOM  has  taken  several  positive  actions  to  address  its  Y2K 
problem.  However,  CENTCOM  and  die  Joint  Staff  have  not  completed 
all  of  the  actions  necessary  to  minimize  the  adverse  impact  of  Y2K  date 
processing  in  mission  and  mission-support  systems.  Progress  is  not 
complete  because  the  Joint  Staff  needs  to  compile  a  comprehensive  list 
of  mission-critical  supporting  systems  for  all  of  the  unified  commands  to 
include  the  system  manager  and  the  status  of  Y2K  compliance.  The 
CENTCOM  needs  to: 

•  identify  the  mission-criticality  of  all  of  its  supporting  systems; 

•  monitor  the  Joint  Staff  unified  command  supporting  systems 
list  and  assess  the  impact  to  the  CENTCOM  area  of  responsibility 
mission  and  develop  operational  contingency  plans  accordingly; 

•  determine  Y2K  compliance  of  vendor  software  and  test 
mission-critical  commercial  off-the-shelf  products; 

•  complete  the  identification  of  system  interfaces  and  prepare 
written  interface  agreements  for  mission-critical  systems  that 
CENTCOM  manages; 

•  develop  contingency  plans  for  CENTCOM-managed 
mission-critical  systems; 

•  document  test  plans  to  show  how  CENTCOM-managed 
systems  were  deemed  compliant  and  determine  the  level  of  Y2K 
compliance; 

•  coordinate  Y2K  solutions  and  contingency  plans  with  its 
component  commands  to  ensure  mission  accomplishment;  and 

•  use  selected  command  and  joint  exercises  to  test  Y2K  scenarios 
in  an  operational  mvironment. 

Unless  tile  CENTCOM,  the  Joint  Staff,  the  Services,  and  Defense 
agencies  collectively  make  further  progress,  CENTCOM  faces  a  high 
risk  that  Y2K-relat^  disruptions  will  impair  its  mission  capabilities. 
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Y2K  Management  Planning,  Strategy,  and  Oversight 

Y2K  Program  Management.  The  GENICOM  Director  of  Command  and 
Control,  Communications,  and  Computer  Systems  (J6)  has  responsibility  for  the 
GENICOM  Year  2000  Program.  The  Director  provides  status  briefings  on 
Y2K  to  the  Commander-in-Chief  on  a  monthly  basis. 

The  GENICOM  has  taken  the  following  actions  as  part  of  its  efforts  to  address 
the  Y2K  problem: 

•  prepared  the  GENICOM  Y2K  project  plan, 

•  appointed  a  Y2K  point  of  contact  for  all  of  GENICOM, 

•  identified  technical  and  management  points  of  contact  for  each 
functional  directorate  and  proponent  organization, 

•  implemented  a  corporate  strategy  to  solve  Y2K  problems  by 
implementing  the  DoD  Management  Plan,  and 

•  established  a  GENICOM  Y2K  web  page. 

The  GENICOM  Y2K  web  page  makes  available  various  Y2K  documents, 
including  the  GENICOM  Y2K  project  plan,  the  systems  inventory  ^tabase, 
minutes  of  the  computer  support  coordinator  meetings,  and  Y2K  points  of 
contact. 

Y2K  Project  Plan.  The  GENICOM  Y2K  project  plan  is  intended  to  provide 
the  overall  strategy  and  actions  necessary  to  accomplish  the  following: 

•  identify  all  GENICOM  systems  that  may  be  affected  by  the  Y2K 
problem, 


•  determine  the  corrective  measures  that  should  be  taken,  and 

•  implement  those  corrective  measures. 

The  project  plan  is  tailored  to  the  DoD  Management  Plan  and  is  intended  to 
address  the  Y2K  problem  by  implementing  the  five  phases  required  by  the  DoD 
Management  Plan.  However,  the  project  plan  does  not  require  the  GENICOM 
to  monitor  changes  to  the  DoD  Management  Plan  and  update  its  plan  based  on 
changes  to  &e  DoD  Management  Plan.  Each  GENICOM  directorate  is  to 
identify  a  point  of  contact  to  cany  out  the  actions  called  for  in  the  project  plan. 
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Y2K  Participation.  The  CENTCOM  addresses  Y2K  issues  at  the  monthly 
computer  support  coordinators  meetings.  Each  CENTCOM  directorate  and  staff 
organization  has  a  computer  support  coordinator.  The  meetings  are  a  forum  to 
discuss  and  address  computer-related  issues,  including  Y2K.  Additionally,  the 
Y2K  point  of  contact  assigns  Y2K  taskings  to  the  computer  support 
coordinators. 


Identification  of  Systems 

The  CENTCOM  identified  469  managed  and  supporting  systems  and  software 
applications  to  fulfill  its  mission  and  everyday  operations.  Managed  systems  are 
those  systems  for  which  CENTCOM  has  program  management  respomibility. 
Supporting  systems  are  those  systems  that  Services  or  other  organizations 
manage.  As  of  January  1998,  CENTCOM  identified  15  CENTCOM-managed 
systems  and  235  supporting  systems.  Additionally,  CENTCOM  determined  that 
it  uses  219  commercial  off-the-shelf  products.  As  the  following  figure 
indicates,  CENTCOM  relies  heavily  on  supporting  systems. 


CENTCOM  Inventory  of  Systems  and  Software 
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Systems  Inventory.  The  CENTCOM  began  developing  a  list  of  software  and 
systems  in  December  1996.  From  December  1996  through  March  1997,  the  J6 
directorate  tasked  die  computer  support  coordinators  to  do  the  following; 

•  review  die  command  standard  and  approved  software  listing  for 
continued  use  and  undocumented  software, 

•  identify  any  networks  and  hardware  within  their  directorates, 

•  identify  any  systems  or  software  within  their  directorates, 

•  identify  any  systems  or  software  within  their  directorates  provided  by 
outside  agencies,  and 

•  inform  tihe  Y2K  point  of  contact  of  potential  Y2K  problems. 

In  July  1997,  the  Director  of  J6  requested  that  all  CENTCOM  directorates  and 
staff  offices  review  the  CENTCOM  Y2K  software  and  systems  listing  for 
accuracy  and  completeness.  In  November  1997,  the  J6  directorate  tasked  the 
computer  support  coordinators  to  review  the  CENTCOM  systems  list  and 
identify  interfaces  for  the  systems  within  their  directorate. 

The  CENTCOM  has  produced  a  software  and  systems  inventory  spreadsheet, 
which  is  available  at  its  Y2K  web  site.  The  spreadsheet  shows  the  status  of 
CENTCOM  systems  to  include  the  following  status  categories:  user, 
mission-critic^ity,  Y2K  compliance,  executive  agent,  Y2K  phase,  renovation 
method,  interfaces,  and  point  of  contact. 

As  stated,  the  CENTCOM  inventory  consists  of  469  systems  and  software 
applications  to  fulftll  mission  and  everyday  operations.  To  determine  the 
potential  impact  of  noncompliance  of  any  of  the  469  systems  and  applications, 
CENTCOM  would  have  to  complete  its  determination  of  the  systems  and 
applications  that  are  mission-critical.  The  following  table  provides  a  breakout 
of  the  status  of  CENTCOM  systems  as  of  January  1998. 

CENTCOM  Systems  and  Applications 


Mission-Critical 


Yes 

No 

Not  Stated 

Total 

CENTCOM-managed  systems 

9 

6 

0 

15 

CENTCOM-supporting  systems 

66 

45 

124 

235 

Commercial  off-the-shelf  products 

12 

54 

146 

219 

Total  systems  and  applications 

94 

105 

270 

469 
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The  J6  directorate  made  a  preliminary  determination  that  94  systems  and 
applications  are  critical  to  die  mission  of  CENTCOM.  However,  CENTCOM 
has  not  determined  mission-criticadity  for  270  supporting  systems  and 
commercial  off-the-shelf  products. 

Systems  Managed  by  CENTCOM.  The  CENTCOM  manages  15  systems. 

Tlie  systems  can  be  categorized  as  the  following: 

•  local  area  networks, 

•  electronic  mail  network, 

•  personnel  locator, 

•  message  processor, 

•  record  of  clearance, 

•  sta^  suspense  system, 

•  personnel  system,  and 

•  update  status  reports. 

The  CK^TCOM  is  the  owner  of  the  code  of  4  of  the  15  systems  that  it 
manages,  and  the  other  11  systems  are  systems  configured  of  commercial 
off-the-shelf  products.  The  CENTCOM  is  planning  to  have  all  of  its  managed 
systems  tested  and  compliant,  not  later  than  October  1,  1998. 

CENTCOM  Supporting  Systems.  The  CENTCOM  has  not  identified  the 
mission-cridcality  and  the  owners  of  all  its  supporting  systems.  Further, 
CENTCOM  has  not  determined  the  status  of  Y2K  compliance  of  its 
mission-critical  supporting  systems.  The  Joint  Stafi'  needs  to  compile  a 
comprehensive  inventory  list  of  mission-critical  supporting  systems  for  all  of  the 
unified  commands  to  include  system  manager  and  status  of  Y2K  compliance. 
Upon  completion  of  the  Joint  Staff  unified  command  supporting  systems  list, 
CENTCOM  needs  to  monitor  and  assess  the  impact  to  ^e  CENTCOM  mission 
area  of  responsibUity  and  develop  contingency  plans  accordingly. 

We  reviewed  the  Services’  and  the  Defense  Information  SysteiM  Agency’s 
mission-critical  systems  lists.  As  of  November  1997,  the  lists  identified  only  20 
of  the  102  supporting  systems  belonging  to  the  Services  and  the  Defense 
I^ormation  Systems  Agency  as  mission-critical.  Further,  CENTCOM 
identified  31  systems  as  mission-critical  that  the  Services  and  die  Defense 
Information  Systems  Agency  did  not  identify  as  mission-critical.  The 
CENTCOM,  with  the  help  of  its  component  commands  and  the  functional 
directorates,  needs  to  complete  the  identification  of  mission-critical  supporting 
systems  because  the  tqipropriate  executive  agents  need  to  be  aware  of  the 
systems  that  are  critical  to  die  CENTCOM  mission.  After  CENTCOM  has 
identified  the  mission-cridcal  supporting  systems,  die  Joint  Staff  should  assist 
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CENTCOM  and  the  other  unified  commands  in  obtaining  Y2K  information  on 
mission-critical  supporting  systems  that  Services  or  other  organizations  manage. 

The  CENTCOM  has  identified  235  supporting  systems  for  which  Y2K 
compliance  is  contingent  upon  another  DoD  Con^onent.  Of  the  235  supporting 
systems,  CENTCOM  has  identified  66  mission-critical  systems, 

45  non-mission-critical  systems,  and  124  systems  of  which  no  determination  has 
yet  been  made  as  to  mission-criticality.  The  CENTCOM  has  not  defined  a 
method  for  determining  the  adverse  impact  of  Y2K  date  processing  in  its 
supporting  systems. 

The  CENTCOM  stated  that  it  had  identified  the  owner  of  all  of  the  systems  that 
CENTCOM  presently  uses.  However,  a  review  of  the  CENTCOM  systems 
inventory  list  indicates  dial  CENTCOM  has  not  identified  the  owner  for  154 
systems  and  applications.  The  CENTCOM  needs  to  complete  die  identification 
of  the  owners  of  its  supporting  systems.  Further,  CENTCOM  needs  to 
determine  the  status  of  diose  systems  and  the  mission-criticality  placed  on  those 
systems. 

The  CENTCOM  has  not  developed  a  method  for  determining  the  status  of  those 
supporting  systems  cridcal  to  its  mission  and,  therefore,  cannot  determine  the 
impact  of  supporting  system  failure  on  the  mission  of  CENTCOM.  The  Joint 
St^  should  develop  and  maintain  a  comprehensive  inventory  list  of 
mission-critical  supporting  systems  and  implement  procedures  to  monitor  and 
track  the  status  of  those  mission-critical  systems,  'l^ose  actions  would  enable 
CENTCOM  and  the  unified  commands  to  monitor  the  progress  of  their 
supporting  systems  and  to  prepare  operational  contingency  plans  for  their 
mission  areas,  accordingly. 

Commercial  Off-the-shelf  Products.  The  CENTCOM  has  not  determined 
Y2K  compliance  for  203  of  219  of  its  listed  commercial  off-the-shelf  products. 
The  DoD  Management  Plan  requkes  that  the  component  not  only  compile  a 
comprehensive  list  of  vendor  software  used  but  also,  during  the  Assessment 
Phase,  determine  whether  the  vendor  software  is  Y2K  compliant.  The  Joint 
Staff  should  coordinate  with  the  Assistant  Secretary  of  Defense  (Command, 
Control,  Communications,  and  Intelligence)  in  obtaining  Y2K  iitfonnation  on 
the  Y2K  compliance  of  vendor  software  and  disseminating  it  to  CENTCOM  and 
the  unified  commands. 


Interfaces  and  Written  Interface  Agreements 

Interfaces.  The  CENTCOM  has  not  completed  identifying  system  interfaces 
and  preparing  written  interface  agreements.  As  a  result,  CENTCOM  is  unable 
to  determine  the  status  of  those  interfaces  that  may  impact  the  mission  of 
CENTCOM.  For  example,  CENTCOM  did  not  identify  the  Global  Command 
and  Control  System  as  a  systems  interface  to  the  CENTCOM  Command  and 
Control  network,  although  the  interface  exists.  The  DoD  Management  Plan 
states  that  interfaces  involve  sending  and  receiving  data  among  Services, 
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Defense  agencies,  or  both,  or  external  DoD  vendors.  Interfaces  are  critical  to 
the  Y2K  effort  because  they  have  the  potential  to  introduce  or  propagate  errors, 
or  bofli,  from  one  DoD  Component  to  another.  The  systems  of  CENTCOM 
interface  with  or  connect  to  many  computer  systems  belonging  to  the  Services, 
DoD  Components,  and  other  organizations.  In  addition  to  known  interfaces, 
CENTCOM  may  interface  with  systems  of  allied,  coalition,  and  other  Federal 
agencies.  Because  diose  systems  are  also  vulnerable  to  Y2K  problems,  they  can 
also  introduce  or  propagate  errors,  or  bofli,  into  CENTCOM  systems.  Timely 
and  complete  information  on  all  system  interfaces  that  may  be  affected  by  Y2K 
changes  is  critical  to  the  success  of  the  Y2K  compliance  program  of 
CENTCOM.  The  CENTCOM  should  complete  the  identification  of  system 
interfaces. 

Written  Interface  Agreements.  The  DoD  Management  Plan  states  that  DoD 
Components  need  to  determine  the  dependency  li^  between  internal  and 
exter^  systems;  determine  dependency  links  between  core  mission  areas, 
processes,  and  all  data  exchange  entities;  and  provide  for  date  and  data  format 
conversions  where  necessary.  A  validation  process  is  necessary  to  ensure . 
compliance.  The  sample  Y2K  compliance  checklist  in  the  DoD  Management 
Plan  states  that  DoD  Components  and  each  interface  partner  should  negotiate  an 
agreement  dealing  with  Y2K  issues.  The  DoD  Components  and  their  interface 
partners  should  discuss  and  verify  that  they  have  implemented  consistent  Y2K 
corrections  for  data  passed  between  the  systems.  The  CENTCOM  needs  to 
prepare  written  interface  agreements  to  i^uce  the  risk  of  discovering  too  late  in 
the  Y2K  effort  that  an  interfacing  system  will  not  be  able  to  accommodate  the 
agency’s  own  Y2K  changes.  The  interface  agreements  should  provide  for  the 
same  types  of  information  as  in  the  DoD  Management  Plan  sample  Year  2000 
Compliance  Checklist. 


Contingency  Plans 

The  CH^TCOM  has  not  developed  contingency  plans  for  any  of  its  managed 
systems.  The  DoD  Management  Plan  states  that  DoD  Comi^nents  should 
develop  realistic  contingency  plans,  including  the  development  and  activation  of 
manual  or  contract  procures,  to  ensure  die  continuity  of  core  processes. 
Contingency  plans  are  to  be  prepared  during  the  assessment  phase  and  should  be 
up^ted  at  each  successive  phase.  The  CENTCOM  stated  in  its  response  to  an 
C^ce  of  the  Inqiector  General,  DoD,  questionnaire  that  it  had  contingency 
plans  for  each  mission-critical  system  in  the  event  that  die  system  fails  to  pass 
testing.  However,  the  contingency  plans  were  not  documented. 
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In  addition  to  system  contingency  plans,  CENTCOM  should  review  and  assess 
contingency  plans  for  mission-critical  supporting  systems,  as  they  become 
available,  and  develop  operational  contingency  plans  as  needed.  The  Joint 
Chiefs  of  Staff  Year  2000  Action  Plan  states  that  the  unified  commands  are  not 
expected  to  know  detailed  information  about  the  mission-critical  systems 
provided  by  the  Services  and  Defense  agencies.  However,  the  unified 
commands  must  conduct  sufficient  planning  and  establish  ^temate  procedures  to 
successfully  complete  the  organization’s  mission  while  the  system’s  program 
managers  and  technical  staff  make  necessary  year  2000  corrections.  The  Joint 
Chiefs  of  Staff  Year  2000  Action  Plan  provides  guidance  on  developing  both 
operational  and  system  contingency  plans. 


Testing  and  Compliance  Checklists 

The  CENTCOM  r^rts  that  8  of  15  managed  systems  are  Y2K  compliant,  and 
3  of  9  mission-critical  managed  systems  are  Y2K  compliant.  The  CENTCOM 
had  tested  and  completed  compliance  checklists  for  4  of  the  15  managed  systems 
but  had  not  provid^  documented  test  plans  to  show  how  the  systems  were 
deemed  compliant. 

Testing.  The  DoD  Management  Plan  states  that  DoD  Components  need  an 
extensive  period  of  time  to  adequately  validate  and  test  converted  or  replaced 
systems  for  Y2K  compliance.  DoD  Components  not  only  must  test  for  Y2K 
compliance  of  individual  applications,  but  must  also  test  the  complex 
interactions  between  scores  of  converted  or  replaced  computer  platforms, 
operating  systems,  utilities,  applications,  databases,  and  interfaces.  All 
converted  or  replaced  system  components  introduced  during  the  "renovation” 
phase  must  be  AorougUy  validated  and  tested  to  uncover  errors,  validate  Y2K 
compliance,  ard  verify  operational  readiness.  The  Joint  Staff  should  assist  the 
unified  commands  in  testing  systems  and  applications  common  to  the  unified 
commands. 

The  CENTCOM  has  a  general  automated  data  processing  contract  in  place, 
which  can  be  used  for  Y2K  testmg.  The  Command,  Control,  Communications, 
and  Computer  Systems  directorate  has  a  computer  laboratory  configured  for 
testing  personal  computer-based  systems  and  limited  testing  of  Sun-based 
systems  or  systems  operating  from  a  Solaris  operating  environment. 

Additionally,  Combat  and  Analysis  has  a  computer  laboratory  setup  for  testing 
Sun-based  systems. 

Compliance  Checklists.  As  stated  in  this  section,  the  contractor  has  validated 
Y2K  compliance  for  4  of  the  15  managed  systems;  1  system  is  mission-critical. 
The  validation  process  requires  the  system  manager  to  complete  the  DoD 
Management  Plan  checklist  and  certify  the  level  of  Y2K  compliance.  Although 
the  contractor  has  signed  the  checklists,  die  contractor  has  not  provided 
documented  test  plans.  Additionally,  the  contractor  did  not  certify  the  level  of 
Y2K  compliance  for  each  of  the  four  systems.  The  Cl^TCOM  ^s  not 
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identified  all  the  system  interfaces  that  require  testing.  The  CENTCOM  should 
test  mission-critical  vendor  software  for  Y2K  compliance  and  should  document 
test  plans  to  show  how  managed  systems  are  Y2K  compliant. 

The  Joint  Interoperability  Test  Command  provides  general  assistance  in  Y2K 
resolution  ti^t  includes  test  planning,  test  case  development,  and  solution 
recommendations.  In  addition,  die  Joint  InteroperabUity  Test  Command  can 
provide  specific  assistance  in  support  of  a  system  to  include  analysis  of 
hardware  platforms  and  software  application  packages,  development  and 
execution  of  a  Y2K  test  plan,  recommendations  to  resolve  Y2K  impacts,  and 
implementation  of  resolution  recommendations. 


Component  Commands 

The  CENTCOM  has  limited  oversight  over  its  component  command 
Y2K  problems  and  solutions,  except  for  interfaces,  because  the  CENTCOM 
component  commands  report  the  Y2K  status  of  those  systems  through  Military 
Departments.  As  a  result,  CENTCOM  does  not  know  how  the  Y2K  is^es  will 
impact  die  overall  mission  of  CENTCOM.  Because  the  CENTCOM  mission 
will  involve  the  component  commands,  the  resolution  strategy  and 
implementation  of  that  strategy  is  a  duid  responsibility  of  CEOTCOM  and  its 
component  commands.  Therefore,  CENTCOM  shoidd  coordinate  Y2K 
solutions  and  contingency  plans  with  the  component  commands,  in  accordance 
widi  the  DoD  Management  Plan. 


Use  of  Selected  Command  and  Joint  Exercises  to  Test  Y2K 
Scenarios 

The  CENTCOM  could  use  selected  command  and  joint  exercises  to  test  and 
measure  the  extent  of  potential  Y2K  problems  that  face  die  warfighter  and  to 
allow  time  to  correct  critical  problems.  The  DoD  Management  Plan  states  that 
testing  shoidd  take  place  in  a  realistic  test  environment  and  should  account  for 
the  interoperability  of  systm  interfaces.  The  use  of  selected  joint  exercises  to 
test  Y2K  scenarios  in  an  operational  environment  would  provide  CENTCOM 
and  the  other  unified  commands  the  opportunity  to  test  and  validate  systems  in  a 
realistic  test  environment. 

Unified  command  exercises  test  o^rational  plans,  validate  force  apportionment, 
support  political  and  military  relationships  and  objectives,  and  foster  regional 
engagements  of  unified  commanders.  Joint  exercises  include  joint  training 
events  based  on  approved  joint  doctrine  that  prepares  joint  forces  or  staffs  to 
respond  to  operatiomd  requirements  established  by  the  combatant  commanders 
to  accomplish  their  assigned  missions.  Mission  focus  is  critical  to  the 
effectiveness  and  efficiency  of  joint  training  exercises.  The  goals  of  joint 
training  are  to  prepare  for  war,  prepare  for  military  operations  other  than  war, 
prepare  for  multinational  operations,  and  integrate  the  interagency  process.  The 
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joint  exercises  focus  on  plans,  policies,  procedures,  and  training  required  to 
ensure  that  senior  leaders  can  effectively  direct  and  integrate  U.S.  and  coalition 
military  forces  during  war.  Common  q)erational  joint  tasks  are  activities 
conducted  by  or  for  multiple  supported  commands  under  similar  conditions  and 
to  a  common  joint  standard.  The  common  tasks  are  selected  by  multiple 
combatant  commands  through  the  mission  analysis  process,  and  they  describe  a 
list  of  core  joint  competencies  that  are  fundamental  to  joint  operations.  The 
common  joint  tasks  include  the  following: 

•  conducting  operational  movement  and  maneuvers, 

•  developing  operational  intelligence, 

•  employing  operational  firepower, 

•  providing  operational  support, 

•  exercising  operational  command  and  control,  and 

•  providing  operational  protection. 

Because  of  time  constraints  posed  by  Y2K  issues,  using  selected  command  and 
joint  exercises  to  test  Y2K  scenarios  may  assist  CENTCOM  in  making  further 
progress  to  identify  and  resolve  Y2K  problems.  Inspector  General,  DoD, 
Report  No.  98-129,  “U.S.  Special  Oj^rations  Command  Year  2000  Issues,” 
May  8,  1998,  reconunended  that  the  Joint  Staff  integrate  year  2000  scenarios 
into  operational  requirements  in  joint  exercises  in  FY  1998  for  die  purposes  of 
determining  the  extent  of  potential  Y2K  impact  on  the  continuity  of  the 
warfighter. 

The  House  bill  to  authorize  appropriations  for  FY  1999  for  the  Department  of 
Defense,  H.  R.  3616,  proposes  tlut  the  Secreta^  of  Defense  submit  to 
Congress  a  report  containing  a  plan  to  include  simulated  Y2K  scenarios  in 
military  exercises  conducted  from  January  1,  1999,  through 
September  30,  1999.  The  plan  shall  include  militaiy  exercises  conducted  under 
the  Chairman  of  the  Joint  Chiefs  of  Staff  Exercise  I^ogram.  Additionally,  the 
plan  is  to  cover  systems  excluded  from  the  exercise  and  provide  an  explanation 
of  how  the  militajy  exercise  will  use  an  excluded  system’s  Y2K  contingency 
plan. 

Performing  command  and  joint  exercises  to  test  Y2K  interoperability  of  system 
interdepertdencies  and  interfaces  may  not  be  possible  in  some  instances  if  the 
Services  and  Defense  agencies  have  not  made  aiKl  implemented  the  necessary 
Y2K  corrections  to  the  required  systems.  In  such  cases,  testing  contingency 
plans  in  an  operational  environment  would  be  necessary.  Testing  contingency 
plans  will  help  CENTCOM  assess  its  capability  to  continue  operations  if 
systems  fail  b^use  of  Y2K  problems. 
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Conclusion 

Although  GENICOM  has  made  initial  progress,  GENICOM  must  continue  to 
address  several  critical  issues.  Ihe  GENICOM  has  recognized  the  importance 
of  solving  Y2K  problems  in  systems  to  reduce  the  risk  of  Y2K  failure,  but 
GENICOM  must  take  a  more  aggressive  approach  to  dealing  with  Y2K  for 
supporting  systems  and  commercial  off-the-shelf  products  to  ensure  that  it  is 
weU-positioned  to  deal  with  unexpected  problems  and  delays.  Unless  the 
Services  and  Defense  agencies  m^e  furtiher  progress,  GENICOM  faces  a  high 
risk  that  Y2K-related  disruptions  will  impair  its  mission  capabilities.  Iherefore, 
GENICOM  must  continually  monitor  and  assess  the  progress  of  supporting 
systems  and  prq)aFe  contingency  plans  for  its  mission  areas,  accordingly.  A 
Joint-Staff-prepared  composite  DoD  mission-critical  database  would  greatly 
facilitate  the  ability  of  GENICOM  and  the  other  unified  commands  to  monitor 
the  progress  of  its  supporting  systems  and  prepare  contingency  plans  for  its 
mission  areas.  Copies  of  this  report  are  being  provided  to  all  unified  commands 
to  facilitate  self  reviews  of  Y2K  efforts. 


Recommendations,  Management  Comments,  and  Audit 
Response 

1.  We  recommend  that  the  Commander  in  Chief,  U.S.  Central  Command: 

a.  Monitor  revisions  to  the  DoD  Year  2000  Management  Plan  and 
implement  the  revisions  into  Uie  U.S.  Central  Command  Year  2000  project 
plan. 


b.  Monitor  the  Joint  Sta^  unified  command  supporting  systems  list 
to  determine  the  status  of  its  supporting  systems  and  assess  the  impact  to 
the  U.S.  Central  Command  area  of  responsibility  mission  and  develop 
operational  contingmcy  plans  accordingly. 

c.  Complete  the  identification  of  mission-critical  supporting  systems 
that  Services  or  other  organizations  manage  and  the  owners  of  aU  of  its 
supporting  systons. 

d.  Complete  the  identification  of  system  interfaces  and  prepare 
written  interface  agreements  for  mission-critical  systems  that  the  U.S. 
Central  Command  manages. 

e.  Develop  contingency  plans  for  U.S.  Central  Command  managed 
mission-critical  systems. 

f .  Review  and  assess  contingency  plans  for  mission-critical 
supporting  systems  and  develop  operational  contingency  plans  as  needed. 
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g.  Research  year  2000  compliance  of  vendor  software  and  test 
mission-critical  vendor  software  for  year  2000  compliance. 

h.  Document  test  plans  to  show  how  managed  systems  were  deemed 
compliant  and  determine  the  level  of  year  2000  compliance. 

i.  Coordinate  year  2000  solutions  and  contingency  plans  with  U.S. 
Central  Command  component  commands. 

j.  Use  selected  command  and  joint  exercises  to  test  year  2000 
scenarios  in  an  operational  environment. 

Management  Comments.  The  U.S.  Central  Command  concurred  with  all  of 
the  recommendations,  stating  progress  made  and  future  intentions  for  each 
recommendation. 

2.  We  recommend  that  the  Director,  Joint  Staff: 

a.  Develop  and  maintain  a  comprehensive  inventory  list  of 
mission-critical  supporting  systems  to  enable  the  unified  commands  to 
monitor  the  progress  of  the  Services  and  agencies  and  to  assess  the  impact 
of  mission  operations. 

b.  Assist  the  unified  commands  in  obtaining  year  2000  information 
on  mission-critical  supporting  systems  that  Services  or  other  organizations 
manage. 


c.  Implement  procedures  to  monitor  and  track  the  status  of 
mission-criticsd  supporting  systems. 

d.  Coordinate  with  the  Assistant  Secretary  of  Defense  (Command, 
Control,  Communications,  and  hitelligence)  to  obtain  and  disseminate 
year  2000  information  on  commercial  off-the-shelf  and  Government 
o^-the-shelf  products. 

e.  Assist  the  uniHed  commands  in  testing  systems  and  applications 
that  are  common  to  the  unified  commands. 

f.  Integrate  year  2000  scenarios  into  operational  requirements  in 
joint  exercises  starting  in  FY  1998  for  the  purposes  of  determining  the 
extent  of  potential  year  2000  impact  on  continuity  of  warfighter  operations. 

Management  Comments.  The  Joint  Staff  concurred  with  all  of  the 
recommendations,  stating  progress  made  and  future  intentions  for  each 
recommendation. 
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Appendix  A.  Audit  Process 


This  report  is  one  in  a  series  of  reports  being  issued  by  the  Inspector  General, 
DoD,  in  accordance  with  an  informal  partnership  with  the  Chief  Information 
Officer,  DoD,  to  monitor  DoD  efforts  to  address  the  Y2K  computing  challenge. 
For  a  listing  of  audit  projects  addressing  this  issue,  see  the  Y2K  webpage  on 
IGnetat  <http://www.ignet.gov>. 


Scope 

We  reviewed  and  evaluated  the  status  of  the  progress  of  CK^TCOM  in 
resolving  the  Y2K  computing  issue.  We  evaluated  the  Y2K  efforts  of 
CENTCOM,  compared  with  those  efforts  described  in  the  DoD  Management 
Plan  issued  by  the  Assistant  Secretapr  of  Defense  (Command,  Control, 
Communications,  and  bitelligence)  in  April  1997.  We  obtained  documentation 
including  the  CENTCOM  Y2K  project  plan,  the  CENTCOM  Y2K  responses  to 
the  Office  of  the  Injector  General,  DoD,  Y2K  questionnaire,  and  systems 
inventory  database  Mormation  as  of  January  1998.  We  used  the  information  to 
assess  efforts  related  to  the  multiple  phases  of  managing  the  Y2K  problem. 

DoD-Wide  Corporate  Level  Government  Performance  and  Results  Act 
(GPRA)  Goals.  In  response  to  the  GPRA,  the  Department  of  Defense  has 
established  6  DoD-wide  corporate-level  performance  objectives  and  14  goals  for 
meeting  the  objectives.  This  report  pertains  to  achievement  of  the  following 
objectives  and  goals. 

•  Objective:  Prepare  now  for  an  uncertain  future.  Goal:  Pursue  a 
focused  modernization  effort  that  maintains  U.S.  qualitative  superiority 
in  key  war  fighting  capabilities.  (DoD-3) 

•  Objective:  Fimdamentally  reengineer  DoD  and  achieve  a  21st  cenhiry 
infl^tructure.  Goal:  Reduce  costs  while  maintaining  required  militaiy 
capabilities  across  all  DoD  mission  areas.  (DoD-6) 

DoD  Functional  Area  Reform  Goals.  Most  major  DoD  functional  areas  have 
also  established  performance  improvement  reform  objectives  and  goals.  This 
report  pertains  to  achievement  of  the  following  functional  area  objectives  and 
goals. 

•  Information  Technology  Man^ement  Functional  Area.  Objective: 
Become  a  mission  partner.  Goal:  Serve  mission  information  users  as 
customers.  (ITM-1.2) 

•  Information  Technology  Management  Functional  Area.  Objective: 
Provide  services  that  satisfy  customer  information  needs.  Goal: 
Modernize  and  integrate  Defense  information  infrastructure.  (ITM-2.2) 


18 


Appendix  A.  Audit  Process 


General  Accounting  OfOce  High-Risk  Area.  The  General  Accounting  Office 
(GAO)  has  identified  several  high-risk  areas  in  the  DoD.  This  report  provides 
coverage  of  the  Information  Management  and  Technology  high-risk  area. 


Methodology 

Audit  Type,  Dates,  and  Standards.  We  performed  this  economy  and 
efficiency  audit  from  January  throu^  March  1998  in  accordance  with  auditing 
standards  issued  by  the  Comptroller  General  of  the  United  States,  as 
implemented  by  the  Inspector  General,  DoD.  We  did  not  use 
computer-processed  data  to  perform  this  audit. 

Contacts  During  the  Audit.  We  visited  or  contacted  individuals  and 
organizations  within  DoD.  Further  details  are  available  upon  request. 

Management  Control  Program.  We  did  not  review  the  management  control 
program  related  to  the  overall  audit  objective  because  DoD  recognized  the  Y2K 
issue  as  a  material  management  control  weakness  area  in  the  FY  1997  Annual 
Statement  of  Assurance. 


Prior  Audit  Coverage 

The  General  Accoimting  Office  and  the  Inspector  General,  DoD,  have 
conducted  multiple  reviews  related  to  Y2K  issues.  Generd  Accounting  Office 
reports  can  be  accessed  over  the  Internet  at  http://www.gao.gov.  Inspector 
General,  DoD,  reports  can  be  accessed  over  the  Internet  at 
http://www.dodig.osd.mil. 
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External  Reporting 

The  DoD  Components  are  required  to  provide  information  to  the  Assistant 
Secretary  of  Defense  (Command,  Control,  Communications,  and  Intelligence) 
on  a  quarterly  basis.  The  reason  for  that  reporting  is  to  give  the  visibility 
necessary  to  ensure  a  thorough  and  success!^]  transition  to  Y2K  compliance  for 
all  DoD  systems. 

Quarterly  Report  Input.  The  quarterly  report  dated  January  16,  1998, 
prepared  by  the  Joint  Staff  and  sent  to  Assistant  Secretary  of  Defense 
(Conunand,  Control,  Communications,  and  Intelligence),  does  not  reflect  the 
status  of  the  CENTCOM  systems.  The  CENTCOM  reported  15  systems  as 
CENTCOM  Y2K  reportable  systems,  9  of  which  it  identified  as  critical  to  its 
mission.  However,  the  Joint  Staff  reported  20  CENTCOM  systems  and 
reported  no  systems  as  mission-criticd.  Based  on  the  documentation  that 
CENTCOM  provided,  the  Joint  Staff  should  have  reported  the  following  to 
Assistant  Secretary  of  Defense  (Command,  Control,  Conununications,  and 
Intelligence)  about  the  CENTCOM  mission-critical  systems: 


Number  being  replaced  5 

Plarmed  terminations  1 

Number  of  non-compliant  systems  6 

Number  of  compliant  systems  3* 

Total  number  of  mission-critical  systems  9 


*Only  one  mission-critical  system  has  been  certified  as  Y2K  compliant. 
CENTCOM  relied  on  vendor  and  in-house  certification. 


Cost  Estimates 

The  CENTCOM  estimates  that  Y2K  compliance  will  cost  $250,000  for  testing 
and  implementation  of  its  systems.  However,  all  CENTCOM-manag^  systems 
and  legacy  systems  will  be  made  Y2K  compliant  as  part  of  fiieir  normal 
life-cycle  maintenance.  The  CENTCOM-developed  software  has  been  rewritten 
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as  part  of  the  CENTCOM  network  migration.  The  CENTCOM  does  not 
anticipate  additional  funding  or  materials  requirements  strictly  for  Y2K 
compliance. 


CENTCOM  Areas  of  Concern 

The  CENTCOM  expressed  concern  about  the  systems  that  are  out  of  its  control. 
The  Cl^TCOM  believes  that  contact  with  program  managers  is  necessary  to 
determine  both  Y2K  solutions  and  status.  The  Joint  Staff  can  provide 
assistance,  especially  with  diose  systems  and  commercial  off-the-shelf  products 
common  to  the  unified  commands.  The  CENTCOM  suggested  that  the  conunon 
operating  environment  is  another  area  of  concern  because  DoD  is  constantly 
changing  die  common  operating  environment.  The  CENTCOM  stated  that  DoD 
needs  to  stabilize  the  operating  environment  until  the  Y2K  problem  has  been 
solved. 
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Office  of  the  Secretary  of  Defense 

Under  Secretary  of  Defense  for  Acquisition  and  Technology 
Deputy  Under  Secretary  of  Defense  (Logistics) 

Director,  Defense  Logistics  Studies  Mormation  Exchange 
Under  Secret^  of  Defense  (Comptroller) 

Deputy  Chief  Financial  Officer 
Deputy  Comptroller  (Program/Budget) 

Under  Secretary  of  Defense  for  Persoimel  and  Readiness 

Assistant  Secretary  of  Defense  (Command,  Control,  Communications,  and  Intelligence) 
Year  2000  Oversight  and  Contingency  Planning  Office 
Assistant  Secretary  of  Defense  (Public  Affairs) 

Joint  Staff 

Director,  Joint  Staff 

Department  of  the  Army 

Assistant  Secretary  of  the  Army  (Financial  Management  and  Comptroller) 

Auditor  General,  Department  of  the  Army 
Chief  Information  Officer,  Army 

Department  of  the  Navy 

Assistant  Secretary  of  the  Navy  (Financial  Management  and  Comptroller) 

Auditor  General,  Department  of  the  Navy 
Chief  Information  Officer,  Navy 

Department  of  the  Air  Force 

Assistant  Secretary  of  the  Air  Force  (Financial  Management  and  Comptroller) 

Auditor  General,  Department  of  the  Air  Force 
Chief  Information  Officer,  Air  Force 
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Unified  Commands 

Commander  in  Chief,  U.S.  European  Command 
Commander  in  Chief,  U.S.  Pacific  Command 
Commander  in  Chief,  U.S.  Atlantic  Command 
Commander  in  Chief,  U.S.  Southern  Command 
Commander  in  Chief,  U.S.  Central  Command 
Commander  in  Chief,  U.S.  Space  Connnand 
Commander  in  Chief,  U.S.  Special  Operations  Command 
Commander  in  Chief,  U.S.  Transportation  Command 
Commander  in  Chief,  U.S.  Strategic  Command 

Other  Defense  Organizations 

Director,  Defense  Contract  Audit  Agency 

Chief  Information  OfiScer,  Defense  Contract  Audit  Agency 
Director,  Defense  Information  Systems  Agency 

Inspector  General,  Defense  Information  Systems  Agency 
Chief  It^ormation  Officer,  Defense  Information  Systems  Agency 
Director,  Defense  Legal  Services  Agency 

Chief  Information  Officer,  Defense  Legal  Services  Agency 
Director,  Defense  Logistics  Agency 
Director,  National  Security  Agency 

Inspector  General,  National  Security  Agency 
Inspector  General,  Defense  Intelligence  Agency 

Non-Defense  Federal  Organizations  and  Individuals 

Chief  Information  Officer,  General  Services  Administration 
Office  of  Management  and  Budget 

Office  of  Information  and  Regulatory  Affairs 
Technical  Information  Center,  National  Security  and  International  Affairs  Division, 
General  Accounting  Office 

Director,  Defense  Information  and  Financial  Management  Systems,  Accounting  and 
Information  Management  Division,  General  Accounting  Office 

Chairman  and  ranking  minority  member  of  each  of  the  following  congressional 
committees  and  subcommittees: 

Senate  Committee  on  Appropriations 

Senate  Subcommittee  on  Defense,  Committee  on  Appropriations 
Senate  Committee  on  Armed  Services 

Senate  Special  Committee  on  the  Year  2000  Technology  Problem 
Senate  Committee  on  Governmental  Affairs 
House  Committee  on  Appropriations 

House  Subcommittee  on  National  Security,  Committee  on  Appropriations 
House  Committee  on  Governmental  Reform  and  Oversight 
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Non-Defense  Federal  Organizations  and  Individuals  (cont’d) 

House  Subcommittee  on  Government  Management,  Information,  and  Technology, 
Committee  on  Government  Reform  and  Oversi^t 
House  Subcommittee  on  National  Security,  International  Affairs,  and  Criminal 
Justice,  Committee  on  Government  Reform  and  Oversight 
House  Committee  on  National  Security 
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U.S.  Central  Command  Comments 


UNn^  mTES  CEPnnAL  COMMAND 
OFHCE  OFTHE  COMMANDER  IN  CHIEF 
7115  SCKTIH  BOUNDARY  BOULEVARD 
lMCD]aAmK»CEBAS£,FLORlDA  3362V5101 


cao 


MEMORANDUM  THRUDIRECTOR,  JOINT  STAFF.  PENTACKR^.  WASHINGTON.  DC 
2031B 

FOR  INSPECTOR  CTNERAL,  DEPARTMENT  OF  DEFENSE.  400  ARMY  NAVY  DRIVE, 
ARLINGTON,  VIRGINIA  22202-2884 

SUBJECT:  Aodit  Repeat  on  U^.  Central  Ccsnmaod  Year  2000  Issues  (Prefect  No. 
8AS-0006.01) 


L  The  AihirBofmymfbnsatkHitedmok^systBSiiswouM  severely  dqpade  my  abiUty^ 
out  thesussiem  ofU^.  Central  Oxmnaad  and  so  lOiank  you  ^pinvi^^  audit  of  our  efforts 

to  solve  tbe  Year  2000  piohlem.  We  have  reviewed  your  audit  report,  concur  widi  foe 
lecoinnieDdatioDs.  and  are  taiemg  actions  to  snpkmcot  foott  zeooDmieDdatkms. 

2.  Spedfic  comments  cm  your  recoinmeiidatiQns  are  enclosed.  We  lemdn  dedicated  to 
tesolviqg  Year  2000 problems  wifo  our  mission-ciitical  information  technology  systems.  My 
point  of  contact  for  Year  2000  issues  is  Lt  Col  Zuzack,  CCJ6-DI,  at  (813)  828-0059. 

DSN  9684)059. 


Coffimander  in  Chief 


U.S.  Central  Command  Comments 


Audit  R^it  on  U^.  Central  Command  Year  2000  Issues  (Project  No.  8AS-0006.01) 

Recofluneidttion  t:  Moidtoricvisions  to  ttieDoD  Year  2000  Minageiaeot  Plan  and 
m^kmeat  die  roviamis  into  the  U.S.  Central  Command  Year  2000  pro] ect  plan. 

USCENTCOMCommeili:  Concur.  U.S.  Central  Comnund’s  Year  2000  Project  Pla^ 
livxngdocuinentba8edoadiecuiientDoDYear2000MaiuigementPlaiL  Chan^tothe 
managemei^plao  can  easOy  be  mcoiporated  into  our  project  plan  as  ^ipropriate. 

RBConuncadatioDb:  Momtor  dm  JamtStaffunifiedcommaiidsqipoitmg  systems  Ust  to 
detennine  dm  Btatim  of  iu  supporting  systems  and  assess  dm  irqiict  to  die  US.  Central 
Command  area  of  leqxmsibility  misQon  and  devdop  opendoiial  omtmgeocy  plans  accordin^y. 

USCENTCOMCoBUMits:  Concur.  IheloiiilStaffisdoiiig  a  good  job  of  consolidating 
information  from  dm  unified  coomiands  and  detennining  dm  status  of  those  systems  that  lifect 
multiple  ClNCs.  Renewing  dmirdocumenlatroo  will  help  us  detennineifwe  ate  at  risk  and 
what  contingency  plans  may  be  necessary. 

RecommendatlM  c:  Complete  dm  ideatification  of  mission-critical  supporting  Qrstems  that 
Services  or  odmr  organizations  manage  arid  die  owners  of  aU  of  its  siqiiport^ 

USCENTCOMCemmeats;  Cmicar.  Progress  in  identiQdngwiiidiofdiesystcnu  in  use 
within  USCENTCOM  and  the  owners  of  dmse  systems  is  a  i^ular  p«t  of  our  Year  2000 
quarterly  tepocts  to  the  Joint  Staff. 

Rcconmcnilatioa  d:  Conqilete  dm  identification  ofaysteminteriaces  arid  prqiare  written 
itdei&ce  agreements  ibr  missioihcriticd  systenm  that  dm  U.S.  Central  Cominan^ 

USCENTCOMConiMts:  Conev.  Progress  mideotify^  systems  ister&ces  is  a  regular  part 
ofoor  Year  2000  quarterly  reports  to  the  Joint  Staff.  We  will  update  toe  reports  to  indicate 
whetoer oroot an  irrteitoce  agreement  exists. 

RccomncndatiMe:  Devebp  contingency  platui^U.S.  Central  Command  xtiinagedtnisn 
critical  aystems. 

USCENTCOMConmiaits:  Concur.  U.S.  Central  Cormnind  staking  action  to  make  our  17 
systems  Year  2000  oompfianl  by  the  end  of  this  yeff  and  have  an  additional  year  to  clean  iqi  ^ 

systems  we  m^  have  missed.  We  do  not  expect  asy  Year  2000  related  problems  to  cause 
catastrophic  faihires.  We  will  prepare  contingency  plans  tor  any  system  whose  progress  begins  to 
slip. 
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Recoumicsdatkin  f:  Review  nd  assess  contingency  plans  for  nussioo-cnticd  supporting 
systems  and  develop  operatioDal  contingeacy  plans  as  needed. 

USCENTCOM  Commcsti:  Concur.  Reviewing  siisaon-critica]  supporting  ^steins 
ccmtingcncy  plans  will  hdp  us  detennine  if  we  are  at  risk  and  wbat  ad^tional  contingency  plans 
be  necessary. 

Recommendation  y  Research  Year  2000  compliance  ofvendor  software  and  test  mission* 
critical  vendor  software  for  Year  2000  compHai:^. 

USCENTCOM  CtHnmcits;  Concur.  We  are  leaearchtng  the  Year  2000  con^liance  status  of 
COTS  products  used  in  USCENTCOM  but  only  diose  products  not  tested  1^  ofoer  federal 
agencies  need  to  be  considered  for  testing  by  USCENTCOM. 

RecoauBoidatioB  h:  Document  test  plans  to  sbcrw  bow  managed  systems  were  deemed 
cmnpliant  and  detennine  the  level  of  Year  2000  oompliance. 

USCENTCOM  Comments:  Concur.  Although  testing  can  not  provide  100%  assurance  a 
problem  will  not  oocttr»  documeatmg  the  tests  win  allow  us  to  know  which  scenarios  have 
ahtady  been  looked  at^  reducing  ftituic  testing  ^uld  problems  occur. 

Recommeaditiott  i;  Coordinate  Year  2000  soludons  and  contiogeocy  plans  with  US.  Central 
Cotmnand  con^onent  commands. 

USCENTCOM  Comments:  Concur.  USCENTCOM  welcomes  the  sharing  of  infonnatioa 
with  its  con^poneot  commands. 

Recommendation  j:  Use  selected  command  andjoint  exercises  to  test  Year2000  scenarios  in 
an  opentiona!  environmeiit 

USCENTCOM  Comments:  Concur.  During  exernses  we  use  operational  systems.  Thus, 
turaing  the  clocks  ahead  duripg  exercises  could  impact  real  wmld  operations.  However,a 
carefully  designed  scenario^  utiliang  systems  isolated  fiom  the  operational  environment,  could 
be  effectivdy  aiMlaafdy  used  to  detetxnine  if  critical  systems  are  ready  for  foe  Year  2000. 
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TMtJOIMT  STAFF 


Reply  2JP  Code:  DJSM  663-98 

20318*0300  June  1998 


MEMORANDUM  FOR  THE  INSPECTOR  GENERAU  DEPAKIMENT  OF 
DEFENSE 

Subject  Audit  Report  on  US  Central  Command  Year  2000  Issues 

1.  The  Joint  Staff  endorses  your  suggestions  to  Improve  the  Year  2000  posture 
of  the  US  Central  Command  (USCENTCOM)-’  We  are  fully  committed  to 
ensuring  the  waifighUng  missions  of  the  combatant  commands  will  be 
conducted  wldsout  Year  2000-rdated  mission  degradation. 

2.  Your  draft  audit  report  induded  findings  for  both  the  Joint  Staff  and 
USCENTCOM.  The  Joint  Staffs  management  comments  on  the  draft  audit  are 
described  in  Endosure  A.  USCENTCOM's  management  comments  are  shown 
at  Endosure  B. 

3.  The  Joint  Staff  point  of  contact  for  Year  2000  actions  Is  Lieutenant  Colonel 
Ramona  Barnes,  J6V.  (703)  695-2117.  DSN  225-2117. 
Tamona.bamesefs.pentagon.mil. 


DENNIS  C.  BLAIR 
Vice  Admiral,  U.S.  Navy 
Director,  Joint  Staff 

Bndosures 

Rderence: 

1  IQ/DOD  memorandum,  22  April  1998,  *Audit  Report  on  U.S.  Central 
Command  Year  2000  Issues  (Project  No.  SAS-OOOS.OIO** 


♦ 

Enclosure  B  not  included  because  CENTCOM  submitted  comments  separately. 
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ENCLOSURE A 

JOINT  STAFF  COMMENTS  ON  AUDIT  REPORT  ON  US  CENTRAL  COMMAND 
YEAR  2000  ISSUES  (PROJECT  NO.  6AS-0006.01) 


R£C(MOIEIIllA!nCMf  1:  Develop  and  ixialntaizi  a  ccmiprehensive  Inventory  list 
of  mission-critical  supporting  ^tems  to  enable  the  unified  commands  to 
monitor  the  progress  of  the  Services  and  agencies  and  to  assess  the  impact  of 
mission  operations. 

JOlirr  STiOT  CQMIIENTS:  Concur.  The  Joint  Staff  Year  2000  Coordinator 
maintains  a  list  of  supporting  ^ems  identified  by  the  combatant  commands. 
The  Department  of  Dtfense  Year  2000  Project  Ofiice  is  developing  a  data  base 
of  all  mission  critical  and  non-mission  ottica]  systems  in  the  Departmoit.  The 
Joint  Staff  and  combatant  commands  will  have  access  to  this  data  base  for 
researching  Y2K  status  of  supporting  ^tems. 

RSCOlOIBNDAXlOir  2.  Assist  the  urUfied  commands  in  obtaining  year  2000 
information  on  mission-critical  supporting  ^tems  that  Services  or  other 
organizations  manage. 

JCHIIT  STAFF  COMMENTS:  We  are  working  dosely  with  the  Services  and 
Defense  agencies  to  ensure  mission  critical  supporting  ^tems  Identified  by  the 
combatant  commands  are  addressed  as  mission  critic^  by  the  ^tem  owners. 
Additionality,  the  Joint  Staff  has  functional  proponents  across  the  staff  who  are 
engaging  on  warfighting  issues  resulting  from  ^e  Year  2000  challenge.  Since 
the  Office  of  the  Secretary  of  Defense  for  Command.  Control.  Communica' 
tions.  and  Intelligence  (OSD/CSQ  dedded  to  tenninate  the  use  of  the  Defense 
Integrated  Suf^rt  Too^  (DISD  data  base  for  Year  2000  reporting,  the  Joint  Staff 
is  adiv^  supporting  tiie  DOD  Y2K  Project  OBict  Initiative  to  create  a  new  DOD 
Y2K  mission  critical  ^tems  data  base  to  give  the  warfighters  visibility  into  Year 
2000  actions  for  all  such  ^sterns  supporting  their  respective  missions. 

KECOMMBNDATICNI 3:  Implement  procedures  to  monitor  and  track  the 
status  of  mission-critical  supporting  systems. 

JCHNT  STAFF  CCttOmrS:  Concur.  The  Joint  Staff  engages  in  significant 
coordination  with  the  Services  and  Defense  agendes  on  Y2K  status  of  mission 
critical  supporting  ^sterns.  The  Joint  Staff's  strong  involvement  in  the 
development  of  a  DOD-wide  ^tems  data  base  to  catalog  Y2K  status  and 
ongoing  initiatives  wiU  further  enhance  the  infonnation  flow. 

RECtHaMENDATlON  4:  Coordinate  with  the  Assistant  Secretary  of  Defense 
(Command.  Control  Communications,  and  Intelligence)  to  obtain  and 
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disseminate  Year  2000  Infonnation  on  commercial  off-the-shelf  and 
Govenunent  oflf-the-shdf  products. 

JOINT  STAFF  COBOIEIITS:  Concur.  The  Joint  Staff  is  actively  engaged  in 
obtaining  Y2K  updates  from  commercial  Industry  and  government  off-the-shelf 
product  suppliers.  This  is  an  area  of  concern  across  the  Federal  government. 

lOCCOIOIBNDATION  5:  Assist  the  un^ed  commands  in  testing  ^tenos  and 
applications  that  are  common  to  the  unified  commands. 

JOINT  STAFF  COIIlIBNTS:  Concur.  The  Joint  Staff  has  been  facilitating  the 
use  of  the  Joint  Interoperability  Test  Command  yiTC)  for  Year  2000  testing  of 
^tems  owned  by  the  unified  commands,  as  well  as  fhost  owned  by  the 
Services  and  Defense  agencies  that  support  combatant  command  missions. 
Additionally,  the  Joint  Staff  engages  the  vendors  that  provide  the  many 
coimnerdal-off-the-shelf  products  common  to  the  combatant  commands  on 
Year  2000  Issues. 

RBCOMMENDAlKni  6.  Integrate  Year  2000  scenarios  into  operational 
requirements  in  Joint  exercises  starting  in  FY 1998  for  the  purposes  of 
detennining  the  extent  of  potential  Year  2000  impact  on  continuity  of 
warfi^ter  qparations. 

JOINT  STAFF  COICBIENTS:  Concur.  The  Joint  Staff  Is  developing  a  Year 
2000  Operadona]  Evaluation  Plan  for  use  by  the  unified  commands  and  the 
Services  during  exercises  and  other  opportunities  from  now  until  Year  2000. 
Our  goal  is  to  ensure  missions  do  not  fail  due  to  Y2K  perturbations. 
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Audit  Team  Members 

The  Acquisition  Management  Directorate,  Office  of  the  Assistant  Inspector 
General  for  Auditing,  DoD,  produced  this  report. 
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Richard  B.  Vasquez 
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